Day-23 Backup & Advanced Topics

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 46

What is Backup?

• Copy data to alternate media Back


Back Up
Up Data
Data
• Prevent data loss
• Only Administrators can backup the data
Backup

Back
Back Up
Up Data
Data Corrupted
Corrupted Data
Data Restore
Restore Data
Data
Windows Backup Admin
Online Backup - Register Server
Online Backup - Register Server
Online Backup - Schedule Backup
Online Backup - Schedule Backup
Online Backup - Schedule Backup
Online Backup - Backup Now
Online Backup - Recover Data
Online Backup - Recover Data
ACTIVE DIRECTORY

• Domain Services (AD-DS)


• Lightweight Directory Services (AD-LDS)
• Rights Management Services (AD-RMS)
• Federation Services (AD-FS)
• Certificate Services (AD-CS)
Lightweight Directory Services (AD-LDS)

• AD LDS Provides an LDAP accessible directory service that supports


identity management scenarios
• Removes all other AD DS features
• No Kerberos authentication
• No forests, domains, DC, GC, sites, group policies

• No dependency on DNS

• Each AD LDS server can host multiple directory stores (i.e. instances)
Lightweight Directory Services (AD-LDS)

• Within each instance


• Schema partition
• Configuration partition
• Zero or more application partitions
Rights Management Services (AD-RMS)

• RMS enables customers to keep internal information internal


• Confidential files protection
• E-mail forwarding
• Web applications

• Benefits:
• Safeguards sensitive internal information
• Digitally enforces organization policies

• Persistently protects information


Rights Management Services Work flow

• Author receives a client license


Databa R MS Active certificate the “first time” they right-
se Server Directo
Server ry protect the information.
• Author defines a set of usage rights
and rules for their file & creates a
“publishing license” to encrypt file.
• Author distributes file.
• Recipient opens the file, the
application calls the RMS server which
validates the user and issues a “use
license.”
• Application opens the file and
Information Author The Recipient enforces rights.
Federation Services (AD-FS)

• AD FS provides an identity access solution


• AD FS is a service that allows for the creation of federated
relationships between organizations for web application
authentication
• Deploy federation servers in multiple organizations to facilitate
business-to-business (B2B) transactions
• AD FS provides a Web-based Single Sign-On (SSO) solution
• AD FS improved in Windows Server 2008
Federation Services (AD-FS)
Gmail.com Orkut.com
• Client contacts Web server to
AD AD access web page
Trust
• Web SSO agent intercepts request
• Client is redirected to FS-R for
discovering the resource
• Client is redirected to FS-A for
Federation Trust Resource
Account
Federation authentication
Federation
Server
Server • FS-A sends the request to Domain
Controller and authenticates user
• Client is redirected back to FS-R
• Web SSO agent intercepts
request, checks authentication,
and sends request to Web server
Web • Client accesses protected content
Server
Certificate Services (AD-CS)

• AD CS Provides PKI certificate issuance and management services


• Not significantly different than CS in 2003
• Provides a certificate issuance and Certification Authority (CA) service
• Issues Digital certificates to web server for Secure data transfer
(HTTPS)
Network Access Protection

Policy Servers
What is Network Access such as: Patch, AV
Protection?

Health Policy Validation Health Policy Compliance


Not policy
compliant Remediation
Servers
Windows DHCP, VPN Restricted
Example: Patch
Client Switch/Router NPS
Network
Ability to Provide Limited Policy
compliant Enhanced Security
Access

Corporate Network
How Network Access Protection works?

Policy Servers
such as: Patch, AV

1 2
Not policy
compliant
4 Remediation
Servers
Windows VPN Restricted
Example: Patch
Switch/Router NPS
Client Network
Policy
compliant

If not policy compliant, client is put in a restricted 5


limited
VPN
Network
If
Client
policyLAN andaccess
orrequests
Policy given
Switch/Router
compliant,
Server access
client
relays
to
(NPS) to fixand
network
is granted up
validates
health resources
status
full
against
presents
access to
to Microsoft
IT-
to
current Corporate Network
15
2
3
4
download
Network
defined
corporate
health patches,
state
health
Policy
network configurations, signatures
policy
Server
(And Repeat 1 - 4)
Network Load Balancing

• Network Load Balancing (NLB) uses a distributed algorithm to balance


IP traffic load across multiple hosts. It helps to improve the scalability
and availability of business-critical, IP-based services.
• NLB also provides high availability, because it detects host failures
and automatically redistributes traffic to surviving hosts.
• Windows Server 2012 NLB clusters can have between 2 and 32 nodes.

• Balances traffic based on node utilization


– New traffic will be directed to the node that is being utilized the least
– You can configure NLB to preference some nodes over others
How NLB Works

Network Load Balancing Host


Accept? Dedicated IP: 10.1.1.2
Virtual IP: 10.1.1.1
No
Network Load Balancing Host
Accept? Dedicated IP: 10.1.1.3
Virtual IP: 10.1.1.1
No
Network Load Balancing Host
Accept? Dedicated IP: 10.1.1.4
Virtual IP: 10.1.1.1
Client Yes
Network Load Balancing Host
Accept? Dedicated IP: 10.1.1.5
Virtual IP: 10.1.1.1
No
Server Failures and Recovery

• NLB cluster heartbeats are transmitted every second between nodes


in a cluster
• Convergence occurs when:
– A node misses five consecutive heartbeats, at which time it is automatically
removed from an NLB cluster
– A node that was member of a cluster returns to functionality

– An administrator adds or removes a node manually

You might also like